Legal
Privacy Policy
This policy explains what personal data Bookessa collects, why we collect it, who we share it with and what rights you have over it. It covers our website, the Bookessa application and the booking pages our customers publish through us.
1. Who we are
Bookessa provides online appointment booking software for service businesses. Businesses use Bookessa to publish a booking page, manage their availability and accept appointments from their own customers.
For the purposes of data protection law, the data controller for the personal data described in this policy is:
We have not appointed a Data Protection Officer, as we are not required to under Article 37 of the GDPR. Privacy questions go to the contact address above and are handled by our team directly.
2. Controller and processor roles
Bookessa handles two different kinds of personal data, and our responsibilities differ for each. This distinction matters, because it determines who you should contact about your data.
We are the controller for account data
When a business signs up for Bookessa, we decide how and why we process the data of that business and its staff — account details, billing information, support conversations and usage logs. For this data we are the controller, and this policy governs it in full.
We are a processor for booking data
When a member of the public books an appointment through a booking page powered by Bookessa, the business receiving that booking decides why the data is collected and what happens to it. That business is the controller; Bookessa is a processor acting on its documented instructions.
Our processing on behalf of business customers is governed by a Data Processing Agreement, which forms part of our Terms of Service.
3. What we collect
We collect only what we need to run the service. We do not buy personal data from third parties, and we do not build advertising profiles.
Information you give us
- Account details — your name, business name, email address and password. Passwords are stored only as salted hashes; we never see or store them in readable form.
- Billing details — legal business name, billing email, billing address and, where you provide one, your VAT or tax identification number. These appear on the invoices issued for your subscription.
- Workspace configuration — the services you offer, their duration and price, your availability, staff members and the content of your booking page.
- Support correspondence — the content of emails and messages you send us, and our replies.
Information we collect automatically
- Authentication and session data — sign-in events, verification codes and session tokens used to keep you signed in securely.
- Technical data — IP address, browser type and version, device type, operating system, language and referring page.
- Usage data — pages viewed, features used, and timestamps of significant actions such as publishing a booking page or changing a plan.
- Diagnostic data — error reports and performance traces generated when something fails, which help us find and fix defects.
Information we receive from others
- Payment status — from Stripe, our payment processor: whether a payment succeeded, the subscription state, plan and billing dates. Stripe may display the card brand and last four digits inside its secure billing portal; Bookessa does not store those card details in its application database. We never receive your full card number.
- Email delivery status — from our email provider: whether a message was delivered, bounced or was marked as spam.
We do not intentionally collect special category data — health, biometrics, religion, political opinions or similar. Some businesses using Bookessa operate in health or wellness, and an appointment record may imply such information. Where that happens, the business is the controller and is responsible for establishing a lawful basis under Article 9 of the GDPR.
4. Why we use it and our legal bases
Under the GDPR we must have a lawful basis for every use of personal data. The table below sets out each purpose, the data involved and the basis we rely on.
Where we rely on legitimate interests, we have assessed that interest against your rights and freedoms and concluded that our processing does not override them. You may object to any such processing — see Your rights.
5. Booking data and end customers
If you booked an appointment through a Bookessa-powered page, the business you booked with decides what information to request. Typically this includes your name, email address, telephone number, the service booked, the appointment time and any note you add.
We store that information so the business can manage the appointment, and we send booking confirmations and reminders on their behalf. We do not use booking data to market to you, we do not sell it, and we do not use it to train AI models that serve other businesses.
6. Payments and billing
Subscription payments are processed by Stripe Payments Europe, Ltd. Card details are entered directly into Stripe's payment form and are transmitted to Stripe, not to us. Bookessa never receives, stores or has access to your full card number, expiry date or security code.
We receive and store a Stripe customer identifier, your subscription status, plan, trial and renewal dates. We use these to show your billing state in the app, reconcile payments and issue invoices. Stripe may show the card brand and last four digits in its secure billing portal, but Bookessa does not store those card details in its application database.
The billing details you enter at checkout — legal name, address and any VAT number — are passed to Stripe so it can produce a valid invoice and calculate tax correctly. Stripe acts as an independent controller for payment processing and applies its own privacy notice, available at stripe.com/privacy.
We retain invoices and the underlying billing records for the period required by tax law in our country of establishment — see How long we keep data.
7. The AI booking assistant
Businesses on our Premium and Pro plans may enable an AI booking assistant that answers questions and takes bookings in conversation on their website.
- The assistant answers from the information the business has approved — its services, prices, availability and its own question-and-answer content.
- Conversation content is processed to generate a reply and is retained so the business can review its own conversations.
- We do not use conversations from one business to train models used by another, and we do not use your conversations to train third-party foundation models.
- Automated replies are not a decision producing legal or similarly significant effects within the meaning of Article 22 of the GDPR. A booking is always confirmed against the business's real availability, and a human at the business can review, change or cancel any appointment.
Please avoid entering sensitive personal information into the assistant. If you need to share something confidential, contact the business directly.
10. International transfers
We aim to keep personal data within the European Economic Area. Our primary database and application infrastructure are hosted in the EU.
Some of our providers are established outside the EEA, or may access data from outside it for support purposes. Where personal data is transferred outside the EEA, we rely on one of the following safeguards under Chapter V of the GDPR:
- an adequacy decision by the European Commission covering the destination country; or
- the European Commission's Standard Contractual Clauses, combined with a transfer impact assessment and, where appropriate, additional technical measures such as encryption in transit and at rest.
You may request a copy of the safeguards we rely on by writing to hello@bookessa.com.
11. How long we keep data
We keep personal data only as long as we need it for the purpose it was collected, or as long as the law requires.
Where we must retain a record for legal reasons, we restrict access to it rather than continuing to use it actively.
12. How we protect data
We take appropriate technical and organisational measures under Article 32 of the GDPR, including:
- Encryption — TLS for all data in transit, and encryption at rest for the database and backups.
- Access control — row-level security so each workspace can reach only its own records, and least-privilege access for our staff.
- Credential hygiene — passwords stored as salted hashes, and email verification codes that expire.
- Isolation of payment data — card details go directly to Stripe and never touch our servers.
- Backups and recovery — regular encrypted backups with tested restoration.
- Monitoring — logging of authentication and administrative events to detect unusual activity.
No system is perfectly secure. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and we will inform you directly without undue delay where the risk is high.
13. Your rights
If the GDPR applies to you, you have the following rights over personal data for which we are the controller.
- Access — obtain confirmation of whether we process your data, and a copy of it.
- Rectification — have inaccurate data corrected and incomplete data completed.
- Erasure — have your data deleted where we no longer have grounds to keep it.
- Restriction — have us pause processing while a dispute about accuracy or legitimacy is resolved.
- Portability — receive the data you gave us in a structured, machine-readable format, and have it sent to another provider where technically feasible.
- Objection — object to processing based on legitimate interests, and to direct marketing at any time. We will stop marketing immediately on request.
- Withdraw consent — where we rely on consent, withdraw it at any time. This does not affect processing carried out before withdrawal.
- Complain — lodge a complaint with your local data protection supervisory authority. Our lead authority is [Supervisory authority of the country of establishment].
To exercise any of these, email hello@bookessa.com. We respond within one month, extendable by two further months for complex requests — we will tell you if that happens and why. We may ask for information to verify your identity, and we will not charge a fee unless a request is manifestly unfounded or excessive.
14. Children
Bookessa is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16 for the purposes of creating an account.
A business using Bookessa may take an appointment for a minor — for example a paediatric clinic or a children's class. In that case the business is the controller and is responsible for obtaining any parental consent required by local law.
If you believe a child has provided us with personal data for which we are the controller, contact us and we will delete it.
15. Changes to this policy
We may update this policy as the service evolves or the law changes. The "last updated" date at the top always reflects the current version.
For material changes — a new purpose, a new category of recipient, or a change that reduces your rights — we will give account holders at least 30 days' notice by email or in-app before the change takes effect. Continuing to use Bookessa after that period means the updated policy applies. If you disagree, you may close your account before it takes effect.
16. How to contact us
For any privacy question, request or complaint, write to hello@bookessa.com with "Privacy" in the subject line, or by post to the registered address in section 1.
We would rather resolve a concern directly than have you go to a regulator, but you always have the right to complain to your supervisory authority without contacting us first.